CVE-2026-52909

In the Linux kernel, the following vulnerability has been resolved: ip6_vti: set netns_immutable on the fallback device. john1988 and Noam Rathaus reported that vti6_init_net() does not set the netns_immutable flag on the per-netns fallback tunnel device (ip6_vti0). Other similar tunnel drivers (like ip6_tunnel, sit, ip6_gre, and ip_tunnel) correctly set this flag during their fallback device initialization to prevent them from being moved to another network namespace.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:*

History

08 Jul 2026, 15:24

Type Values Removed Values Added
CWE NVD-CWE-noinfo
References () https://git.kernel.org/stable/c/12acc977838c943636fb01e2f3087d2e4cc3b7cc - () https://git.kernel.org/stable/c/12acc977838c943636fb01e2f3087d2e4cc3b7cc - Patch
References () https://git.kernel.org/stable/c/12c65e2c7fef507551bd7b52123598a761662c01 - () https://git.kernel.org/stable/c/12c65e2c7fef507551bd7b52123598a761662c01 - Patch
References () https://git.kernel.org/stable/c/7f28e3948c59481f8db9c9638e204258d26b4e41 - () https://git.kernel.org/stable/c/7f28e3948c59481f8db9c9638e204258d26b4e41 - Patch
References () https://git.kernel.org/stable/c/c5dbd669db5a426b3025512322e1bf2cdbe14305 - () https://git.kernel.org/stable/c/c5dbd669db5a426b3025512322e1bf2cdbe14305 - Patch
References () https://git.kernel.org/stable/c/d289d5307762d1838aaece22c6b6fcad9e8865f9 - () https://git.kernel.org/stable/c/d289d5307762d1838aaece22c6b6fcad9e8865f9 - Patch
References () https://git.kernel.org/stable/c/dcdce3bc9f08026ff3739ee7339e1bef526fc5f3 - () https://git.kernel.org/stable/c/dcdce3bc9f08026ff3739ee7339e1bef526fc5f3 - Patch
References () https://git.kernel.org/stable/c/ecf8904067dcba0dad86ece80874841e60317885 - () https://git.kernel.org/stable/c/ecf8904067dcba0dad86ece80874841e60317885 - Patch
References () https://git.kernel.org/stable/c/f4b6b4af7ef0661ac153c6f7eb1030aa8482c1a3 - () https://git.kernel.org/stable/c/f4b6b4af7ef0661ac153c6f7eb1030aa8482c1a3 - Patch
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*
First Time Linux linux Kernel
Linux

04 Jul 2026, 12:16

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/12acc977838c943636fb01e2f3087d2e4cc3b7cc -
  • () https://git.kernel.org/stable/c/12c65e2c7fef507551bd7b52123598a761662c01 -
  • () https://git.kernel.org/stable/c/7f28e3948c59481f8db9c9638e204258d26b4e41 -
  • () https://git.kernel.org/stable/c/c5dbd669db5a426b3025512322e1bf2cdbe14305 -
  • () https://git.kernel.org/stable/c/f4b6b4af7ef0661ac153c6f7eb1030aa8482c1a3 -

28 Jun 2026, 08:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

19 Jun 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-19 15:16

Updated : 2026-07-08 15:24


NVD link : CVE-2026-52909

Mitre link : CVE-2026-52909

CVE.ORG link : CVE-2026-52909


JSON object : View

Products Affected

linux

  • linux_kernel